supply-chain North Korean Hackers Blamed for Mastra NPM Supply Chain Attack A malicious dependency the attackers added to over 140 Mastra packages fetches a payload targeting cryptocurrency extensions. The post North Korean Hackers Blamed for Mastra NPM Supply Chain Attack appeared first on Secu… SecurityWeek · Jun 22, 2026
supply-chain Microsoft links Mastra AI supply chain attack to North Korean hackers Microsoft has attributed a recent supply chain attack targeting over 140 npm packages to the North Korean hacking group Sapphire Sleet, also known as BlueNoroff. The attack involved compromising an npm maintainer account… BleepingComputer · Jun 20, 2026 High KPsupply-chainnpmcryptocurrency
supply-chain Klue OAuth breach victim list grows as Icarus hackers claim attack A security breach at Klue, a market intelligence platform, has resulted in the theft of OAuth tokens used to connect to customer Salesforce environments. The attack, attributed to the ‘Icarus’ extortion group, impacted m… BleepingComputer · Jun 19, 2026 High USoauthsalesforcedata breach
supply-chain Cybersecurity Firms Impacted by Klue Supply Chain Attack A supply chain attack targeting the Klue market intelligence platform resulted in the unauthorized harvesting of customer data from various integrations, including Salesforce and HubSpot. The attack, attributed to a new… SecurityWeek · Jun 19, 2026 High supply-chainoauthcrm
supply-chain Accenture to Acquire Majority Stake in Dragos, All of runZero, NetRise in $4.1 Billion OT Cybersecurity Push Accenture is undertaking a significant investment in operational technology (OT) cybersecurity through a series of acquisitions, totaling approximately $4.1 billion. This includes a majority stake in Dragos, along with t… SecurityWeek · Jun 18, 2026 High USot securityindustrial control systemsasset discovery
supply-chain ShapedPlugin update flow hacked to infect WordPress sites A supply-chain attack targeting WordPress plugins from ShapedPlugin resulted in malicious updates containing a backdoor designed to steal sensitive data from affected websites. The attack exploited a compromised build pi… BleepingComputer · Jun 18, 2026 High CVE-2026-10735CVE-2026-49777wordpresssupply chainbackdoor
supply-chain 144 Mastra npm Packages Compromised via Hijacked Contributor Account A software supply chain attack, dubbed ‘easy-day-js,’ compromised 144 npm packages within the Mastra namespace by hijacking a contributor account. The attack leveraged a malicious dependency, ‘easy-day-js,’ to deploy a c… The Hacker News · Jun 17, 2026 High supply chainnpmjavascript
supply-chain GitHub dismissed security reports on flaws now exploited by supply-chain worm, researchers say A supply-chain worm, dubbed Shai-Hulud, is exploiting design flaws in GitHub to infect hundreds of software packages and developer accounts worldwide. The vulnerabilities, initially flagged by Deep Specter Research, were… The Record · Jun 16, 2026 High GBFRsupply chainvulnerabilitygithub
supply-chain Google Vertex AI SDK Flaw Let Attackers Hijack Model Uploads via Bucket Squatting A vulnerability in the Google Cloud Vertex AI SDK allowed attackers to hijack model uploads by exploiting predictable bucket naming conventions. Attackers could create a temporary bucket in their own project, intercept t… The Hacker News · Jun 16, 2026 High CVE-2026-2473USbucket squattingmodel uploadcloud storage
supply-chain Atomic Arch Supply Chain Attack Hits 1,500 AUR Packages Arch Linux suspended account registrations in response to the wave of malicious packages being uploaded to AUR. The post Atomic Arch Supply Chain Attack Hits 1,500 AUR Packages appeared first on SecurityWeek . SecurityWeek · Jun 16, 2026
supply-chain Pickle in the Middle – Hijacking Vertex AI Model Uploads for Cross-Tenant RCE A vulnerability in the Google Cloud Vertex AI Python SDK (versions 1.139.0 - 1.140.0) allowed attackers to hijack model uploads and execute remote code execution (RCE) within a target's Vertex AI serving infrastructure.… Palo Alto Unit 42 · Jun 16, 2026 High sdkrcebucket squatting
supply-chain OptinMonster WordPress plugin hacked in CDN supply-chain attack A supply-chain attack targeting the Awesome Motive CDN compromised WordPress plugins OptinMonster, TrustPulse, and PushEngage. Attackers gained access through a vulnerability in the UpdraftPlus plugin, leveraging the CDN… BleepingComputer · Jun 15, 2026 High UScdnwordpresssupply chain
supply-chain NPM 12 Will Change Script Execution Behavior to Prevent Supply Chain Attacks By default, npm install will no longer execute scripts from dependencies, unless explicitly allowed. The post NPM 12 Will Change Script Execution Behavior to Prevent Supply Chain Attacks appeared first on SecurityWeek . SecurityWeek · Jun 13, 2026
supply-chain Early Warning Signs of Supply-Chain Attacks Live in the Dark Web This BleepingComputer article highlights the increasing threat of supply-chain attacks, which target the tools and vendors organizations rely on. The article details how early warning signs of these attacks often appear… BleepingComputer · Jun 12, 2026 High GEsupply chaingithubcredentials
supply-chain GitHub to Disable npm Install Scripts by Default to Stop Supply Chain Attacks GitHub has announced what it said are "breaking changes" coming to npm version 12, one of which turns off install scripts by default to combat software supply chain threats. The changes aim to combat attack techniques th… The Hacker News · Jun 11, 2026
supply-chain The ‘Miasma’ worm source code briefly leaked on GitHub The source code for the Miasma credential-stealing worm framework, previously linked to supply-chain attacks targeting open-source ecosystems, was briefly leaked on GitHub. This leak, mirroring the earlier Shai-Hulud wor… BleepingComputer · Jun 10, 2026 High USsupply chaincredential theftopen source
supply-chain GitHub announces npm security changes to tackle supply-chain attacks GitHub has announced that npm v12, expected next month, will introduce several security-focused changes aimed at blocking supply-chain attacks abusing behaviors triggered by the 'npm install' command. BleepingComputer · Jun 10, 2026
supply-chain Miasma Supply Chain Worm Burrows Into 73 Microsoft Repositories A sophisticated supply chain attack, orchestrated by the Miasma worm (a variant of Shai-Hulud), targeted 73 Microsoft GitHub repositories, primarily within the Azure organization. The attack, initially discovered through… Dark Reading · Jun 9, 2026 High supply chaingithubazure
supply-chain Microsoft Restores Some GitHub Repos, Keeps Others Offline as Miasma Probe Continues Microsoft is investigating a recent security incident involving the compromise of 73 open-source GitHub repositories as part of the ongoing "Miasma" supply chain attack. The attackers, utilizing a technique involving inf… The Hacker News · Jun 9, 2026 High supply chainopen sourceinformation stealer
supply-chain GitHub disables Microsoft repos pushing password-stealing malware Microsoft repositories on GitHub were temporarily disabled on June 5th due to concerns about distributing malware, specifically linked to the ongoing Miasma/Shai-Hulud supply-chain campaign. The incident involved the com… BleepingComputer · Jun 9, 2026 High USsupply-chain attackgithubmalware